HomeCyber Threat ReportSeptember 2026

Cybersecurity Threat Report — September 2026

The September 2026 edition tracks a surge in ransomware victims, a wave of actively exploited flaws in the internet-facing edge gear small offices actually run, and the growing role of AI in phishing and wire fraud. Written in plain English for owners and one-person IT teams at companies of 10–250 people, it closes with an eight-step action plan. Every figure is tied to a named, dated source.

Published by NetSys Group engineers · September 2026 edition · Updated October 4, 2026

The month in four numbers

  • 7,551 ransomware victims disclosed in a year, up 24.9% (Black Kite 2026)
  • $20.9B in reported U.S. cybercrime losses in 2025, a record (FBI IC3 2025)
  • 55 minutes, the fastest observed break-in to full encryption (Arctic Wolf, 2025)
  • 15 SMB products added to CISA's exploited-flaw list (CISA KEV, Aug 2026)

Bottom line up front

Threat level: Elevated. Attackers are mass-exploiting the internet-facing devices small offices run, and ransomware now encrypts in under an hour. The good news: the fixes below are cheap and within reach.

If you do only three things:

  1. MFA on remote access. Put phishing-resistant MFA on email, VPN and every admin login.
  2. Patch the edge now. Update internet-facing VPNs, firewalls, mail and RMM tools this week.
  3. Verify payments by phone. Confirm any bank-detail change on a number you already have.

Ransomware and extortion

Small business is the target now: the $1M to $5M revenue band nearly doubled its share of victims, and active groups grew to 146 by June (Black Kite 2026).

Groups we're watching:

  • Qilin: most active this year, with 1,358 disclosed victims.
  • Akira: breaks in through SonicWall VPNs with weak or reused logins and goes from a stolen login to full encryption in under four hours, sometimes 55 minutes (Arctic Wolf, 2025).
  • Cl0p: mass data theft; it claimed roughly 89GB from Shell via a third-party tool on Aug 17.
  • Medusa: still going, with 500+ organizations breached since 2021 and active in August.

Each starts the same way: an internet-facing login without MFA, or an edge device left unpatched. Close those two doors and most attacks never begin.

AI threats and wire fraud

AI has industrialized phishing. 90% of high-volume phishing runs on "phishing-as-a-service" kits, and 70% of malicious PDFs hide a QR code that jumps the attack to a phone (Barracuda 2026 Email Threats Report). The typos are gone, so treat unexpected requests, not bad grammar, as the warning sign.

Wire fraud is where money goes. Business email compromise took $3.04B in 2025, and 86% moved by wire or ACH (FBI IC3 2025). For a 40-person shop, that is a payment-verification problem, not antivirus.

One habit stops most wire fraud: when anyone asks to change bank details or rush a payment, confirm on a phone number you already have on file, never the one in the email. Deepfaked voices and look-alike addresses make the request itself untrustworthy; the call-back is what protects you.

Your team already uses AI. Gen-AI prompts per company jumped sixfold in a year, to about 18,000 a month, and nearly half runs through personal accounts, leaking code, client data and logins (Netskope Cloud & Threat Report 2026). Give staff one sanctioned tool; a ban just hides the data where you can't see it.

Breaches to learn from

  • Zimbra mail: 274 servers compromised, 8,200+ still unpatched. Patch self-hosted mail or move it to a managed service.
  • Beacon CRM: one leaked cloud key exposed 1,000+ charities at once. A shared platform can breach every tenant; you can be hit without being attacked.
  • RingCentral: a social-engineering attack exposed 1.6M accounts; the attackers say they phoned an employee and talked them out of a password. The phone, not just email, is now a way in, so verify callers.
  • CareCloud: a health-IT vendor breach exposed 3.75M patient records. Small practices inherit their software vendor's exposure; ask about theirs.

The cost of deepfakes

Organizations hit by deepfake fraud lost $450K on average, and 1 in 10 lost more than $1M (Veriff 2026). AI-enabled fraud reported to the FBI reached $893M in 2025 (FBI IC3 2025). Cloned voices and video calls are now cheap, so the defense is a process, not a gut check: verify unusual money or data requests through a second, known channel.

Patches that can't wait

40 flaws hit CISA's exploited list in six weeks; 15 are in gear a small office runs, six of them VPNs, firewalls and gateways. If a box lets staff in from outside, attackers try it first, so patch it first.

ProductFlawAdded to CISA KEV
Citrix NetScaler ADC / GatewayCVE-2026-8452Aug 26
Cisco Secure Firewall ASA / FTDCVE-2026-20349Aug 11
Fortinet FortiOSCVE-2025-68686Jul 27
N-able N-central (RMM)CVE-2026-18577Aug 3
Zimbra CollaborationCVE-2026-73570Aug 21
Microsoft SharePointCVE-2026-50522Jul 22

Don't forget the boring boxes. ownCloud and a decade-old Linux bug joined the exploited list in August, and Langflow, Ray and MLflow are now actively exploited, so lock down any AI experiment exposed to the internet. PaperCut is back under attack; quiet internal servers are common ransomware on-ramps. A current inventory of every internet-facing and server system is your cheapest security control.

The inbox is still the front door. About a third of firms see at least one hijacked mailbox a month; attackers read, wait and pounce on a real invoice. What helps: phishing-resistant MFA, alerts on new forwarding rules and logins, and a staff briefing that urgency, not typos, is the red flag.

What changed

  • FTC Safeguards Rule: tax preparers, auto dealers and advisers must now run MFA and encryption, with no size exemption and fines up to $53,088 per violation.
  • State privacy laws: 20 states now have consumer-privacy laws in force, and Texas and Nebraska set no small-business size floor.

If you hold customers' financial or personal data, "too small to matter" is no longer a defense. The good news: these rules require MFA, encryption, a written plan and backups, the same basics that stop the attacks in this report.

Cheaper cover, few takers: only 10 to 20% of small firms carry cyber insurance, against 62% overall (Munich Re 2026). Yet 2026 pricing keeps softening, and roughly $1,200 to $2,400 a year buys $1M of cover.

Your 8-step action plan

  1. Turn on phishing-resistant MFA everywhere, preferring passkeys or FIDO2.
  2. Patch internet-facing gear this week.
  3. Verify every payment change by phone.
  4. Keep offline, tested backups, and rehearse the restore.
  5. Give staff one sanctioned AI tool.
  6. Ask your MSP how fast they patch, especially RMM tools.
  7. Review cyber insurance now.
  8. Run a 30-minute phishing drill.

Sources and method: this edition draws on primary and government reporting from the CISA Known Exploited Vulnerabilities Catalog (July to August 2026), the Black Kite 2026 Ransomware Report, the FBI IC3 2025 Annual Report, Arctic Wolf (Akira / SonicWall), the Barracuda 2026 Email Threats Report, the Netskope Cloud & Threat Report 2026, Veriff 2026, Munich Re 2026, the FTC Safeguards Rule and a state-privacy-law tracker. Every figure is attributed where it appears. Where trackers disagreed we used the most directly verifiable primary source; annual figures unchanged since our August edition are noted as context, not new findings.

The designed PDF edition, with charts, is free. One short form on the main report page unlocks this edition and every other one. Get the PDF

Beyond the report

Discuss the security controls behind the headlines.

Share the systems, data and risks your business needs to protect. A NetSys engineer can discuss monitoring, identity protection, backups and incident response within an agreed scope.

Explore Cybersecurity Services 845-203-3914